Browser Extension
Right-click any indicator on any page: an IP, domain, URL, hash, CVE or email, and check it against ThreatIntellix without switching tabs. Requires the Pro plan or above, same as the MCP server and TAXII feed.
1. Install the extension
The extension isn't on the Chrome Web Store yet: it ships as source in the browser-extension/ folder of the ThreatIntellix repository, and loads as an unpacked extension in developer mode:
- Open
chrome://extensions(or the equivalent in any Chromium-based browser, e.g.edge://extensions). - Turn on Developer mode (top right).
- Click Load unpacked and select the
browser-extension/folder.
2. Get an API key
In Settings → API keys, generate a key (the same key used for the TAXII feed and MCP server). Copy it immediately, it's only shown once.
3. Connect it to your deployment
Click the extension icon and choose Settings (or right-click the icon → Options). Enter your deployment URL and the API key from step 2, then save. You'll be asked to grant the extension permission to reach that one host, scoped to it specifically rather than every site you visit.
4. Using it
- Select any indicator on a page, right-click, and choose Check with ThreatIntellix. The extension detects what kind of indicator it is automatically.
- Or click the toolbar icon and paste a value directly, useful for indicators that aren't on a page at all.
- If the extension can't tell what something is, it asks you to pick the type before looking it up.
What it checks
The same three sources exposed to the MCP server and used throughout the app, queried through one endpoint rather than three separate tool calls:
- IPs, domains, URLs: AlienVault OTX and VirusTotal, in parallel.
- File hashes and CVEs: AlienVault OTX.
- Email addresses: Have I Been Pwned.